Repository navigation
External Access
This document describes options for accessing the Kubernetes cluster's services from outside your local network.
There are two primary methods for providing external access to your cluster's services:
- Cloudflare as a Reverse Proxy
- Tor Hidden Services
Each method has its own advantages and use cases.
Cloudflare can act as a reverse proxy for your services, providing additional security, caching, and DDoS protection.
-
Register a Domain: If you don't already have one, register a domain name to use with Cloudflare
-
Add Domain to Cloudflare:
- Create a Cloudflare account if you don't have one
- Add your domain to Cloudflare and update your domain's nameservers
-
Configure DNS Records:
- Create DNS records for each service you want to expose
- Example:
argocd.example.com→ Points to your home IP address
-
Set Up Port Forwarding:
- Configure your router to forward incoming traffic on ports 80 and 443 to your ingress controller's IP address (172.16.100.251)
-
Enable Proxy Status:
- Enable the orange cloud (proxy) for each DNS record in Cloudflare
-
SSL/TLS Settings:
- Set SSL/TLS encryption mode to "Full" or "Full (strict)"
- Create origin certificates if using "Full (strict)"
-
Additional Security Rules (Optional):
- Set up Cloudflare access rules to restrict access to specific countries or IP ranges
- Configure Web Application Firewall (WAF) rules
- DDoS Protection: Cloudflare absorbs attack traffic
- Caching: Improves performance for static content
- TLS Termination: Handles SSL/TLS encryption
- Hide Origin IP: Your home IP is not directly exposed
- Analytics: Provides insights on traffic
Tor hidden services (onion services) provide an alternative way to access your services with enhanced privacy and without requiring port forwarding or a public IP address.
-
Install Tor:
apt update && apt install -y tor -
Configure Tor as a Hidden Service:
- Edit
/etc/tor/torrc:
HiddenServiceDir /var/lib/tor/hidden_service/ HiddenServicePort 80 172.16.100.251:80 HiddenServicePort 443 172.16.100.251:443 - Edit
-
Restart Tor:
systemctl restart tor
-
Get Your .onion Address:
cat /var/lib/tor/hidden_service/hostname
-
Access Services:
- Use the Tor Browser to access your services via the .onion address
- No Port Forwarding: Works behind NAT without port forwarding
- No Public IP Required: No need for a static IP or dynamic DNS
- Enhanced Privacy: Traffic is encrypted and routed through the Tor network
- Access Control: The .onion address is difficult to discover without sharing it
You can implement both methods simultaneously to provide different access options for different scenarios:
- Use Cloudflare for general access, especially for services that benefit from caching
- Use Tor hidden services for more private access or as a backup method
Regardless of the access method, consider these security measures:
- Authentication: Implement strong authentication for all exposed services
- Regular Updates: Keep your cluster and applications updated
- Access Logs: Monitor access logs for suspicious activity
- Rate Limiting: Implement rate limiting to prevent brute force attacks
- Ingress Rules: Only expose services that need external access
-
SSL/TLS Errors:
- Verify SSL/TLS mode is set correctly
- Check certificate validity
-
DNS Propagation:
- DNS changes may take time to propagate
- Use
digor online DNS lookup tools to verify
-
Connection Refused:
- Verify the Tor service is running
- Check if the specified ports are correctly routed to your ingress controller
-
Slow Connections:
- Tor networks can be slower than direct connections
- This is normal and expected